PHP is a widely embedded server-side scripting language that powers a substantial portion of the web infrastructure, from shared hosting environments to enterprise content management systems, making its vulnerability footprint exceptionally consequential despite a focused product portfolio. Vulnerabilities affecting the PHP interpreter and its standard library skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code. The recurring exposure centers on the core PHP interpreter, the PEAR package manager, and related extensions, clustering around memory-safety issues including out-of-bounds reads, integer overflows, buffer-boundary violations, and improper input validation—flaws typical of a large C codebase handling untrusted user input and complex protocol parsing. Because PHP runs on millions of web servers globally and often lags in patching, defenders should treat PHP interpreter updates as high-priority and track both direct installations and bundled distributions such as FrankenPHP. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by PHP Group over time
Of all the CVEs published by PHP Group as a CNA, 98.9% affect products that PHP Group develops as a vendor.
Of all the CVEs published that affect products developed by PHP Group, 11.5% are self-published by PHP Group as a CNA.
Signals from CVEs in this vendor scope (777 CVEs).
777 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4577CRITICAL In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m | Jun 9, 2024 | 9.8 | 99 | YES | YES |
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2019-11043CRITICAL In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff | Oct 28, 2019 | 9.8 | 98 | YES | YES |
CVE-2020-28949HIGH Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succe | Nov 19, 2020 | 7.8 | 95 | YES | YES |
CVE-2015-0235HIGH Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code | Jan 28, 2015 | 10.0 | 92 | NO | YES |
CVE-2020-36193HIGH Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. | Jan 18, 2021 | 7.5 | 91 | YES | NO |
CVE-2018-19518HIGH University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap | Nov 25, 2018 | 7.5 | 90 | NO | YES |
CVE-2018-7584CRITICAL In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream | Mar 1, 2018 | 9.8 | 85 | NO | YES |
CVE-2011-4885MEDIUM PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of | Dec 30, 2011 | 5.0 | 81 | NO | YES |
CVE-2005-1921HIGH Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such a | Jul 5, 2005 | 7.5 | 78 | NO | YES |
Signals from CVEs in this vendor scope (777 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by PHP Group.
Media articles that mention a CVE ID that affects a product developed by PHP Group — matched by CVE ID, not by vendor name.